Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Anthropic's September Report — Chinese Labs' 200M-Exchange Claude Distillation, Russian AI Espionage, Bioweapons Blocked (20260911)

Anthropic's fourth threat-intelligence report (December 2025–August 2026) accuses seven China-based labs of industrial-scale Claude distillation — Alibaba's 151M-exchange Qwen campaign via 3,500+ fake accounts, Moonshot silently rerouting Kimi user requests (23M exchanges, including a PLA-affiliated user's Chengdu CCTV query), and DeepSeek's 12M+ exchanges — alongside a Midnight Blizzard-linked AI campaign against Ukraine, a Changsha 'exploit foundry,' and blocked biological-misuse cases. Also today: CISA KEV adds MikroTik CVE-2026-67277/CVE-2026-86060; Check Point patches two CVSS-9.8 VPN flaws; Fortinet fixes FortiMonitor OnSight CVE-2026-84390 (9.6) and FortiSandbox CVE-2026-26084; Vivotek hit by Everest ransomware; Wiz ties JFrog Artifactory CVE-2026-42018/-42016 chain to admin takeovers; Cisco FMC hosts deployed Qilin ransomware; PaperCut mass exploitation reaches 395 organizations in 48 countries.

Anthropic Claude AI-Misuse Model-Distillation Alibaba Moonshot-AI DeepSeek Xiaomi Zhipu Russia Midnight-Blizzard Bioweapons CISA-KEV MikroTik CVE-2026-67277 CVE-2026-86060 Check-Point CVE-2026-85102 CVE-2026-85103 Fortinet CVE-2026-84390 CVE-2026-84388 CVE-2026-26084 F5 CVE-2025-53521 Cisco-FMC CVE-2026-20079 CVE-2026-20316 Qilin Sandworm JFrog CVE-2026-42018 CVE-2026-42016 Sogou UNC3569 GRAYRABBIT PaperCut CVE-2026-81578 CVE-2026-82078 ShinyHunters Vishing Microsoft-365 Vivotek Everest Gitea CVE-2026-60004 Silver-Fox Kinryu-Labs Taiwan CISO-Digest

Anthropic’s September Misuse Report: Chinese Labs’ Industrial Distillation, Russian AI Espionage — and Blocked Bioweapons Research

On September 10, Anthropic published “Detecting and countering misuse of AI: September 2026” — its fourth threat-intelligence report (following March, August and November 2025) — covering operations it disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. The report’s cases involve suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions and politically motivated individuals; Claude Haiku, Sonnet and Opus models were used, and — with one distillation exception — no case involved Fable- or Mythos-class models.

The headline finding is industrial-scale “illicit distillation” by China-based labs. Anthropic named Alibaba, Moonshot, DeepSeek, Xiaomi and Zhipu among the seven China-based labs it says ran unauthorized campaigns to extract Claude’s most valuable capabilities — agentic reasoning, software engineering and logical reasoning — and says the combined activity totaled close to 200 million exchanges between May and July. The mechanics:

  • Alibaba ran what Anthropic calls the largest distillation campaign it has ever documented: more than 151 million Claude interactions from May through July, peaking at nearly 3 million a day across more than 3,500 fraudulent accounts — transcripts used to help train Alibaba’s Qwen models. A June letter to US senators had already flagged ~28.8 million exchanges from roughly 25,000 fake accounts, after which Alibaba banned Claude Code for employees, citing security risks.
  • Moonshot (maker of Kimi) routed some live user requests to Claude without informing customers, then displayed Claude’s responses as if they were Kimi’s: over one 10-day period it relayed nearly 300,000 customer requests through a network of 5,380 fraudulent accounts, with total distillation activity exceeding 23 million exchanges. In one case, a user Anthropic assessed as PLA-affiliated asked Kimi to analyze CCTV surveillance footage from hundreds of cameras in Chengdu — and Moonshot passed the material to Claude.
  • DeepSeek silently relayed customer conversations too, with 12 million-plus exchanges logged in just two weeks of July; in one instance the relayed requests exposed live credentials for a Russian government database.
  • The funnel was a network of “transfer stations” — intermediary services operating outside China that created accounts on US AI services using fake identities, stolen or forged credit cards and stolen API keys. Anthropic says the practices “are likely inconsistent with privacy laws and the labs’ own terms of service.” Beijing has dismissed US distillation allegations as “groundless” (our September 9 digest), while the White House OSTP director said in July that Moonshot distilled Anthropic outputs while developing Kimi K3, and the Treasury Secretary has warned that sanctions and Entity List designations are “on the table.”

Beyond distillation, the report logs AI-enabled espionage and weapons work. A hacking group whose tradecraft is consistent with Russia’s Midnight Blizzard allegedly ran phishing, hotel Wi-Fi hijacking and WhatsApp-takeover operations against Ukrainian government, military and diplomatic targets, using AI at nearly every stage — including a system that automatically detected when its malware was flagged by defenses and rewrote the code until it evaded detection again. A Changsha-based group that Anthropic describes as two university undergraduates turned Claude into an “exploit foundry”: they split it into sub-agents to run reconnaissance and post-intrusion tasks simultaneously while retaining target lists, stolen credentials and attack instructions — in one month-long operation against network equipment, more than 10 candidate zero-days were identified and roughly 50 organizations selected as targets. The report also discloses software-development support for firearms, missiles, armed drones, bombs and their targeting and control systems in China, Russia and Yemen; multiple biological-misuse cases (including a user seeking information needed to modify avian influenza to infect mammals — “In the past we thought of this type of misuse as a hypothetical risk, but now we are seeing real cases,” said threat-intelligence head Jacob Klein); a French hacker’s doxxing site; manipulation of Malaysian election-related opinion by a Turkish company; networks of fake dating apps; and disrupted activity linked to ShinyHunters affiliates.

Anthropic is blunt about the trend: “A majority of the operations… were enabled by AI via direct execution or orchestration” — going “beyond simple questions and responses from a chatbot” to multi-agent frameworks executing tasks, with humans as overseers rather than hands-on operators.

Why This Reshapes AI Platform Governance and Enterprise Risk

  • End-user data can transit foreign models without consent. The Moonshot case shows user material — including CCTV analysis of an individual — flowing through one lab’s routing layer into a third-party model, and DeepSeek relayed requests that exposed live credentials to a foreign government database. Any AI toolchain that touches these services now carries unmapped data-transit exposure, including privacy-law and contractual risk its users never opted into.
  • The distillation dispute is now evidence-backed and two-sided. This week’s joint NSA/FBI/CISA advisory (our September 9 digest) called distillation “the critical core” of these labs’ development programs; Anthropic’s case-level detail — accounts, volumes, techniques, user-data exposure — gives regulators, procurement teams and litigators concrete material, while Beijing calls the accusations smears.
  • Orchestration, not autonomy, is the threat model to plan for. Multi-agent operations that find zero-days, rewrite flagged malware and harvest credentials at machine speed — against existing enterprise software — compress detection and response windows; identity and behavior are the durable control points, not payload signatures.

🔗 Reference: Coverage from (Anthropic — Detecting and countering misuse of AI: September 2026, CNBC, Quartz, The Straits Times, iThome)


Active Threats This Week

📌 JFrog Artifactory flaws chained into admin takeover and backdoors (CVE-2026-42018 / CVE-2026-42016) Wiz says attackers chained two Artifactory flaws between August 15 and September 8 to gain administrator control of self-hosted servers and plant backdoors. CVE-2026-42018 makes Artifactory hand an internal anonymous-user token to callers who never logged in — even when anonymous access is disabled; CVE-2026-42016 then lets that low-privilege token be exchanged for one with administrator scope, because Artifactory validates a token’s signature and issuer but not what it is allowed to do. In some cases the first request reached a new admin account in under five minutes, and administrator actions performed this way are logged as token:anonymous rather than a named account. JFrog shipped fixes before the attacks (April 28 on the 7.146 branch; August 12 on 7.133), so only unupgraded servers are exposed; either fix closes the chain. 🔗 Reference: The Hacker News

📌 China-linked UNC3569 exploited a Sogou input-method flaw to deploy GRAYRABBIT Gen Digital found the flaw while investigating a live UNC3569 intrusion: a crafted link abused Sogou Input Method — China’s dominant Chinese-character input tool, with 455 million-plus monthly users per Citizen Lab’s 2023 research — to install the group’s long-used GRAYRABBIT backdoor (remote command shell, two-way file transfer, on-demand modules). Tencent fixed the entry point in April 2026, but Gen notes the fix did not change what made the attack possible: the patched build it examined still ships a 2020-era browser engine with its sandbox switched off. Google Threat Intelligence ties UNC3569 to China’s hacker-for-hire scene, tracked since 2021 and targeting government, education, technology and finance, mostly in East and Southeast Asia. 🔗 Reference: The Hacker News

📌 PaperCut swaps emergency patches for tested maintenance releases — as AI-agent mass exploitation reaches 395 organizations PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 replace the earlier emergency patches for CVE-2026-81578 and CVE-2026-82078 with fully QA-tested maintenance releases (plus additional hardening). The flaws remain under active exploitation: GreyNoise and Blackpoint Cyber now attribute at least 395 breached organizations across 48 countries — mostly US education — to a suspected Russian-speaking actor, with attacks driven by hundreds of AI agents powered by OpenAI’s Codex harness and a DeepSeek model. Campaign traffic comes from 45.142.193[.]132 (the address our September 5 coverage tied to school credential theft), and the targeting skips Russia, China, Hong Kong, Thailand, Iran and 23 other countries. 🔗 Reference: The Hacker News

📌 Cisco FMC exploited by three clusters — state espionage, a Sandworm-linked implant, and Qilin ransomware Cisco Talos detailed three post-compromise clusters abusing the KEV-listed CVE-2026-20079 (CVSS 10.0) and CVE-2026-20316 (CVSS 5.3) in Secure Firewall Management Center: UAT-12197 deployed JSP web shells and a JAR-based command executor, querying internal databases for authentication data and credentials; UAT-11823 delivered a Netcat-based reverse shell, bash scripts harvesting managed-device configurations, and a variant of Cyclops Blink — the modular implant previously attributed to Russia’s Sandworm; and UAT-11988, a ransomware operation that used CVE-2026-20316 for initial access, lived off built-in FMC tooling to reconnoiter, tunnel and collect credentials, then deployed Qilin ransomware. (CISA added CVE-2026-20079 to KEV on September 9 — covered in our September 10 digest.) 🔗 Reference: The Hacker News | iThome

📌 Vivotek: Everest ransomware claims 236 GB theft as Delta denies system impact Ransomware group Everest claimed on September 1 to have breached Vivotek, a Delta Electronics subsidiary whose IP cameras and recorders are widely deployed: it says it stole 236 GB — nearly 95,000 files including firmware, source code and development, testing and maintenance data, and published a 56-page technical document while demanding payment. Delta says its investigation found no affected systems and no sensitive-data leak, arguing the material matches files Vivotek distributes publicly, some of it old. Threat-intel firm SOCRadar found 23 infostealer records referencing vivotek[.]com spanning January 2025 to September 1, 2026 — including 2 employee credentials, 5 customer credentials and a third-party credential — evidence of infected machines inside the vendor’s perimeter. 🔗 Reference: iThome

📌 CISA KEV: MikroTik RouterOS CVE-2026-67277 and CVE-2026-86060 — federal deadline September 13 CISA’s September 10 KEV update lists two MikroTik RouterOS flaws — CVE-2026-67277 (missing authentication for a critical function) and CVE-2026-86060 (improper handling of delimiters in command arguments) — with exploitation observed and a federal remediation deadline of September 13. The additions follow CERT Polska, which used AI-assisted analysis to identify multiple RouterOS weaknesses and reported that some have been exploited in attacks since September 2. (RouterOS SSH hijacking was flagged in our September 6 digest.) 🔗 Reference: iThome

📌 Check Point patches two CVSS 9.8 VPN flaws (CVE-2026-85102 / CVE-2026-85103) Check Point’s September 9 advisory covers two critical VPN vulnerabilities that can let unauthenticated attackers execute remote code. CVE-2026-85102 (VPN negotiation) affects security gateways and Check Point Spark firewalls with site-to-site or remote-access VPN enabled; CVE-2026-85103 (ASN.1 decoding of VPN certificates) is a heap overflow affecting security management servers, security gateways and Spark appliances. Both are rated 9.8. Check Point says it discovered the flaws itself, has seen no signs of active exploitation, and directs customers to deploy the latest Jumbo Hotfix. 🔗 Reference: iThome

📌 Fortinet fixes 10 flaws — FortiMonitor OnSight JWT bypass (9.6), FortiPAM, FortiSandbox (8.9) Fortinet’s September 8 advisories cover 10 vulnerabilities, two of them critical. CVE-2026-84390: forged or previously used JWT tokens bypass portal authentication on FortiMonitor OnSight (CVSS 9.6; affects 7.2.0–7.2.2 and 7.2.4–7.2.7; fixed in 7.2.8). CVE-2026-84388 affects the FortiPAM agent’s Chrome extension (improper authentication). Also notable: FortiSandbox CVE-2026-26084 (improper access control, CVSS 8.9) — unauthenticated attackers can reach sensitive information through crafted HTTP requests on FortiSandbox 4.4/5.0, FortiSandbox Cloud 5.0 and FortiSandbox PaaS 5.0 — a system that had known flaws exploited in the wild months ago. 🔗 Reference: iThome | iThome

📌 F5 BIG-IP APM: new exploitation wave deploys purpose-built Linux malware (CVE-2025-53521) Sophos found Linux malware built specifically for F5 BIG-IP APM environments, delivered by exploiting CVE-2025-53521 (CVSS 9.3) — the APM flaw disclosed in October 2025 that CISA warned in March was being exploited. The implant is a second-stage payload; a companion component infects /usr/sbin/httpd, tampers with SELinux configuration and abuses BIG-IP upgrade images to persist. Its targeting of Apache/libphp/APR module-loading, the BIG-IP APM Webtop component and the BIG-IP update flow shows tradecraft purpose-built for the platform. 🔗 Reference: iThome

📌 Vishing-first account takeovers: Microsoft tracks Storm-3032 / Storm-3121 BYOD campaigns; ShinyHunters hits healthcare Two developments put voice phishing at the center of account takeover. Microsoft has tracked Storm-3032 and Storm-3121 since May: attackers call or text executives and administrators on personal devices, impersonate IT helpdesks, and push “update your passkey/MFA/SSO” lures that lead to adversary-in-the-middle and device-code phishing pages, capturing credentials and session tokens; they then register their own MFA devices for persistence and exfiltrate corporate data through the Microsoft Graph API — likely passing access to extortion groups including ShinyHunters. Separately, Health-ISAC warned that ShinyHunters is running vishing campaigns against healthcare, registering lookalike domains that combine employer names with security terms, then pivoting from SSO into Microsoft 365, SharePoint and Salesforce to steal data for extortion. These campaigns extend the vishing-first takeover pattern covered in our September 8 digest (Arctic Wolf’s PREY-0058) — with personal devices now serving as the entry path that bypasses corporate security stacks. 🔗 Reference: Dark Reading | iThome

📌 Google Play’s Early Access program abused to push thousands of deceptive apps Bitdefender documented large-scale abuse of Google Play Early Access: because Early Access apps cannot receive public reviews or star ratings, the trust signals users normally rely on are absent — and attackers have used the gap to push thousands of deceptive applications (fake casino games, reward apps, misleading utilities and trademark-infringing titles), including a Grand Theft Auto lookalike, “Vice Streets: Open World,” with more than 1 million downloads. The apps are promoted through TikTok and Facebook ads featuring celebrity deepfakes, promising cash rewards, PayPal payouts, cryptocurrency, gift cards and jackpots. “The same feature that shields developers from unfair criticism also strips users of the earliest warning that an app cannot be trusted,” Bitdefender said. 🔗 Reference: The Hacker News

📌 Shadowserver: 8,300+ Gitea servers still exposed to CVE-2026-60004 (RCE) Shadowserver warns that 8,393 internet-facing Gitea instances remain vulnerable to CVE-2026-60004, a critical flaw found by Salesforce researcher Shai Rod: a crafted patch sent to the diffpatch API endpoint by anyone with repository write access installs a malicious Git hook that executes commands as the Gitea service user. Because Gitea enables open registration by default, attackers can create their own account and repository to trigger it. Fixed July 27 in 1.27.1; CISA added it to KEV in late August, and the bug is already being exploited in real attacks. The vulnerable servers are concentrated in China, Germany and the US. 🔗 Reference: Xakep

📌 Kinryū Labs: 220 million flight records exposed via Vietnam APIS database Singapore research startup Kinryū Labs disclosed on September 9 an exposed Elasticsearch database in Hanoi tied to a flight passenger information system (APIS): 220 million passenger and crew records spanning January 2017 to April 2026 and 1,008 airlines, including names, dates of birth, gender, nationality, passport numbers, flights, airports, seats and baggage data. The database still used Elasticsearch default credentials and was reachable from a cloud path despite being meant to refuse public access. Found June 3 and locked down June 8 after notifications to Vietnamese authorities, airlines and CERTs (Singapore Airlines’ security team helped coordinate); whether the data was copied elsewhere — and who operated the database — remains unresolved. 🔗 Reference: iThome

📌 Silver Fox resurfaces: trojanized installers target multinationals’ China offices Microsoft detailed a campaign attributed to suspected China-based actor Silver Fox: fake download sites for trusted software — Edge, Kaspersky, Razer utilities, Youdao Dictionary, Baidu Netdisk, Sogou Input Method — aimed at simplified-Chinese users and the China offices of multinational corporations, with victims already recorded across healthcare, manufacturing, gaming, technology, logistics, government and education. Downloads are dynamically generated (same filename, different hash each time) and include Windows Installer-packaged payloads; once executed, the malware sets SYSTEM-level scheduled tasks, tampers with Defender allowlists, disables Microsoft Update components, deletes Volume Shadow Copy backups and injects code — sometimes with hands-on operator activity — before moving laterally over SMB. (The group appeared in our September 8 digest over Kaspersky’s ValleyRAT campaigns; Microsoft’s research documents a separate, broader operation.) 🔗 Reference: iThome

📌 Taiwan moves to mandate breach reporting as ransomware pressure builds Premier Cho Jung-tai said encrypted-ransomware attacks now span technology, manufacturing, healthcare, retail and tourism — impacting not just business operations but social stability and national security — and directed the Ministry of Digital Affairs (MODA) to serve as the cross-agency threat-intelligence coordinator: draft security guidance for private enterprises, bring major intrusion and ransomware cases under statutory reporting obligations, and establish government–enterprise–law-enforcement intelligence sharing and early-warning mechanisms. The National Police Agency was separately tasked with strengthening technical investigation, digital forensics and specialist recruitment. 🔗 Reference: iThome


How Can OPSWAT Help

Several of today’s campaigns ride inside files that enter through routine user and developer channels: Silver Fox’s dynamically generated fake installers (same filename, different hash — evading simple signature checks), thousands of deceptive Google Play Early Access APKs, and malicious patches and hooks delivered through developer infrastructure (Gitea’s diffpatch abuse, JFrog Artifactory backdoors). MetaDefender Multi-Scan layers 30+ anti-malware engines over executables, installers and archives to catch what single-engine stacks miss, while MetaDefender CDR (Content Disarm & Reconstruction) rebuilds allowed files — stripping active content from documents, scripts and archives traversing email, web and developer upload paths — and MetaDefender Kiosk screens files at physical and OT boundaries.